Last updated: 2025-11-30 19:16:13 +0100
unclassified (108)
??: 108
Average staleness: 401 / Average age: 553
unknown (35)
Major: 1 / Normal: 5 / Minor: 13 / Trivial: 10 / ??: 6
Average staleness: 847 / Average age: 1219
tracker (25)
Normal: 1 / ??: 24
Average staleness: 452 / Average age: 1005
| Bug | Severity | Summary | Status | Stale | Age |
|---|---|---|---|---|---|
| 915553 | Normal | [Tracker] HTTP/2 Rapid Reset vulnerability CVE-2023-44487 Tracked bugs: 8 open / 14 total | 107 | 782 | |
| 824306 | ?? | [Tracker] Vulnerability in gstreamer (CVE-2021-3522) CVE-2021-3522 Tracked bugs: 1 open / 2 total | 1473 | 1473 | |
| 792267 | ?? | [Tracker] Packages misusing libsoup API for TLS validation Tracked bugs: 5 open / 5 total | 1193 | 1649 | |
| 807352 | ?? | [Tracker] NO STARTTLS collection of vulnerabilities Tracked bugs: 2 open / 18 total | 1193 | 1573 | |
| 811909 | ?? | [Tracker] ElGamal Plaintext Recovery in dev-libs/botan CVE-2021-40529 Tracked bugs: 1 open / 2 total | 1193 | 1545 | |
| 924455 | ?? | [Tracker] "KeyTrap" DNS DoS vulnerability CVE-2023-50387 CVE-2023-50868 Tracked bugs: 4 open / 5 total | 649 | 655 | |
| 643228 | ?? | [TRACKER] kernel: Meltdown and Spectre - A flaw in modern processors (CVE-2017-{5715,5753,5754}) Tracked bugs: 1 open / 7 total | 637 | 2888 | |
| 643342 | ?? | [TRACKER] hw: cpu: speculative execution branch target injection (CVE-2017-5715) CVE-2017-5715 Tracked bugs: 1 open / 11 total | 637 | 2887 | |
| 920280 | ?? | [Tracker] Terrapin Vulnerability CVE-2023-48795 Tracked bugs: 4 open / 10 total | 589 | 713 | |
| 932373 | ?? | [Tracker] Mozilla Foundation Security Advisory for May 14/15th, 2024 CVE-2024-4367 CVE-2024-4767 CVE-2024-4768 CVE-2024-4769 CVE-2024-4770 CVE-2024-4777 MSFA2024-21 MSFA2024-22 MSFA2024-23 Tracked bugs: 263 open / 10000 total | 558 | 558 |
upstream (94)
Major: 4 / Normal: 26 / Minor: 46 / Trivial: 13 / ??: 5
Average staleness: 945 / Average age: 1446
| Bug | Severity | Summary | Status | Stale | Age |
|---|---|---|---|---|---|
| 626822 | Major | media-libs/libmad: Dos (memory corruption) via crafted MP3 files CVE-2017-11552 | 1676 | 3043 | |
| 907924 | Major | dev-python/reportlab: remote code execution CVE-2023-33733 | 908 | 908 | |
| 866386 | Major | app-arch/unzip: null pointer dereference CVE-2021-4217 | 784 | 1194 | |
| 901393 | Major | app-admin/doas: vulnerable to privilege escalation via TIOCSTI/TIOCLINUX command injection CVE-2023-28339 | 327 | 991 | |
| 721672 | Normal | CVE-2018-20225 | 2032 | 2032 | |
| 617474 | Normal | x11-libs/cairo: NULL pointer dereference with a crafted font file (CVE-2017-7475) CVE-2017-7475 | 1590 | 3132 | |
| 810034 | Normal | media-libs/plib: integer overflow leading to code execution (CVE-2021-38714) CVE-2021-38714 | 1559 | 1559 | |
| 717714 | Normal | 1505 | 2054 | ||
| 845039 | Normal | dev-embedded/u-boot-tools: unbounded memcpy in nfs CVE-2022-30767 | 1294 | 1294 | |
| 829835 | Normal | sys-devel/patch: invalid free vulnerability CVE-2021-45261 sys-devel/patch: Double free allowing DoS in another_hunk (CVE-2019-20633) | 1201 | 1439 |
upstreamebuild (31)
Normal: 9 / Minor: 14 / Trivial: 7 / ??: 1
Average staleness: 671 / Average age: 1229
| Bug | Severity | Summary | Status | Stale | Age |
|---|---|---|---|---|---|
| 798480 | Normal | app-text/djvu: multiple vulnerabilities (CVE-2021-{3500,32490,32491,32492,32493}) CVE-2021-32490 CVE-2021-32491 CVE-2021-32492 CVE-2021-32493 CVE-2021-3500 | 1430 | 1619 | |
| 759544 | Normal | www-misc/awstats: Arbitrary code execution (CVE-2020-35176) CVE-2020-35176 | 1202 | 1814 | |
| 821346 | Normal | 1135 | 1489 | ||
| 836920 | Normal | sys-apps/busybox: multiple vulnerabilities CVE-2022-28391 CVE-2022-30065 | 842 | 1334 | |
| 793953 | Normal | net-dns/avahi: multiple DoS vulnerabilities CVE-2021-3468 CVE-2021-3502 CVE-2021-36217 CVE-2023-1981 CVE-2023-38469 CVE-2023-38470 CVE-2023-38471 CVE-2023-38472 CVE-2023-38473 | 756 | 1642 | |
| 918403 | Normal | media-libs/tiff: crafted input results in out-of-memory CVE-2023-6277 | 737 | 737 | |
| 897952 | Normal | app-text/htmltidy: arbitrary code execution CVE-2021-33391 | 520 | 1008 | |
| 838382 | Normal | media-sound/sox: multiple vulnerabilities CVE-2021-23159 CVE-2021-23172 CVE-2021-23210 CVE-2021-33844 CVE-2021-3643 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 CVE-2023-26590 CVE-2023-32627 CVE-2023-34318 CVE-2023-34432 | 350 | 1325 | |
| 966254 | Normal | sys-boot/grub: multiple vulnerabilities CVE-2025-54770 CVE-2025-54771 CVE-2025-61661 CVE-2025-61662 CVE-2025-61663 CVE-2025-61664 | 11 | 11 | |
| 638434 | Minor | sys-libs/db: Berkeley DB reads DB_CONFIG from the current working directory CVE-2017-10140 | 1995 | 2930 |
ebuild (45)
Critical: 2 / Major: 5 / Normal: 12 / Minor: 17 / Trivial: 7 / ??: 2
Average staleness: 681 / Average age: 897
| Bug | Severity | Summary | Status | Stale | Age |
|---|---|---|---|---|---|
| 918679 | Critical | dev-libs/stb: multiple vulnerabilities CVE-2023-43281 CVE-2023-43898 CVE-2023-45661 CVE-2023-45662 CVE-2023-45663 CVE-2023-45664 CVE-2023-45666 CVE-2023-45667 CVE-2023-45675 CVE-2023-45676 CVE-2023-45677 CVE-2023-45678 CVE-2023-45679 CVE-2023-45680 CVE-2023-45681 CVE-2023-45682 | 602 | 733 | |
| 937483 | Critical | net-wireless/wpa_supplicant: possible privilege escalation CVE-2024-5290 | 218 | 480 | |
| 942684 | Major | sys-cluster/slurm: Incorrect Authorization CVE-2024-48936 | 252 | 394 | |
| 953891 | Major | www-client/firefox{-bin,}: multiple vulnerabilities CVE-2025-3608 | 228 | 229 | |
| 953892 | Major | mail-client/thunderbird{-bin,}: multiple vulnerabilities CVE-2025-2830 CVE-2025-3523 | 226 | 229 | |
| 966445 | Major | net-libs/webkit-gtk: multiple vulnerabilities CVE-2025-43392 CVE-2025-43425 CVE-2025-43427 CVE-2025-43429 CVE-2025-43430 CVE-2025-43431 CVE-2025-43432 CVE-2025-43434 CVE-2025-43440 | 6 | 6 | |
| 965825 | Major | app-containers/containerd: multiple vulnerabilities CVE-2024-25621 CVE-2025-64329 GHSA-m6hq-p25p-ffr2 GHSA-pwhc-rpq9-4c8w | 5 | 22 | |
| 802513 | Normal | net-analyzer/fail2ban: code exection via malicious whois responses (CVE-2021-32749) CVE-2021-32749 | 1208 | 1598 | |
| 821220 | Normal | <sys-devel/gcc-12.1.0: Unicode "bidirectional override" (CVE-2021-42574) | 1204 | 1490 | |
| 868150 | Normal | CVE-2020-10735 | 1145 | 1184 |
stable? (22)
Major: 5 / Normal: 3 / Minor: 14
Average staleness: 31 / Average age: 133
stable (8)
Major: 1 / Normal: 2 / Minor: 5
Average staleness: 33 / Average age: 157
| Bug | Severity | Summary | Status | Stale | Age |
|---|---|---|---|---|---|
| 965719 | Major | <app-containers/runc-{1.2.8,1.3.3}: Multiple vulnerabilities CVE-2025-31133 CVE-2025-52565 CVE-2025-52881 | 23 | 25 | |
| 921521 | Normal | <mail-mta/sendmail-8.18.1: smtp smuggling CVE-2023-51765 | 127 | 694 | |
| 956398 | Minor | <dev-db/pgagent-4.2.3: Insecure temporary directory use CVE-2025-0218 | 50 | 193 | |
| 958341 | Minor | <net-misc/sslh-2.2.4: Multiple vulnerabilities CVE-2025-46806 CVE-2025-46807 | 50 | 165 |
cleanup (199)
Critical: 1 / Major: 30 / Normal: 33 / Minor: 121 / Trivial: 9 / ??: 5
Average staleness: 360 / Average age: 584
glsa? (621)
Major: 13 / Normal: 102 / Minor: 488 / Trivial: 3 / ??: 15
Average staleness: 540 / Average age: 830
glsa (0)
| Bug | Severity | Summary | Status | Stale | Age |
|---|
